CVE-2026-82183

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 06:17

Updated : 2026-09-03 17:50


NVD link : CVE-2026-82183

Mitre link : CVE-2026-82183

CVE.ORG link : CVE-2026-82183


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication